Hacking into Internet-Connected Light Bulbs
contextis.co.uk
contextis.co.uk
In an effort to make the UI accessible from the outside (for me), I forwarded the Raspberry Pi's HTTP server port to the server where I host my normal web stuff. Only I screwed up the proxy rule in the NginX config. All of a sudden, lights and blinds went haywire all over the house.
Turns out whoever visited any of my domains at the time got the HA control panel instead. And people clicked on the devices!
There's absolutely no authentication on the network protocol at all; as long as you're in the same network as the bulbs then you can send UDP packets and control the bulbs. I imagine this is a good and a bad thing; XBoxes automatically setting mood lighting when playing games etc... I'd rather they had to ask my permission before doing that, though.
[0] https://github.com/magicmonkey/lifxjs/blob/master/Protocol.m...
Disclaimer: I work on AllJoyn.
https://git.allseenalliance.org/cgit/lighting/service_framew... https://allseenalliance.org
Is it just some excuse to con investors into buying stocks in some insanely valued IPOs?
I don't mean to be negative and I understand the value of information in our economic life, but how much info is required from the internet of things to support our home life of eating, drinking, fornicating, watching TV and going to bed at the end of day?
who keeps all this info and what to they do with it?
You gotta admit thermostats have a purpose for being connected though. It's nice to have your thermostat know you're coming home or going away, and adjust things accordingly.
Also doors with locks of all kinds. It's very interesting to have your key be your smartphone.
It's also very interesting for thiefs to unlock said doors without physically breaking in, causing noise and so on.
Which means you can sell internet connected home alarms.
When all is said and done, we'll be all "internet of things". Things that do stuff, and things that protect us from the side effects of the first things. The possibilities are endless.
As for their purpose, well, to the company it's too make money, to the buyers, that's explained by this classic¹ strip of C&H: http://assets.amuniversal.com/6e921050df960131725e005056a954...
¹ yes, it's redundant, I know
Now your light bulb is unreliable as well as your computer :)
The light bulb halting problem, now: Will it turn off? Impossible to say.
The bulb in question here has not just one, but two processors that both run faster than the 100MHz 486. Also, when Windows 95 came out - in 1996 - the minimum required RAM was 4MB. The ST processor in the light bulb has built in RAM of 1MB. So, in theory, it would be possible with a few hacks to get the bulb to run MS Windows 95...
EDIT: I guess it was OSR2 in 1996... still, the light bulb is a decent computing machine in comparison to early to mid-90s consumer tech...
"few"
Sentences like that make me happy. I love the hacker spirit.
Is it spelled correctly? Can you give me a link to it? I'm interested in home automation, but all the ones I've looked into so far don't really do it for me.
Here is a article [1] describing a setup involving this type of RGB light and the raspberry. It also covers some other type of RGB lights.
The wifi bridge has been sitting on my desk for a while now. not bothered yet since the remote is sufficient for now. So can not really comment on that. Otherwise happy with one of the cheaper alternatives. No problems as of yet. Waiting for my lights to get switched on and off though :D The remote doesn't require line of sight as its RF, and already has quite the range.
[1] http://iqjar.com/jar/home-automation-using-the-raspberry-pi-...
Recently I created a little node service that listens to events from our site from RabbitMQ and flashes the Hue lightbulbs when interesting things happen.
http://blog.cyberexplorer.me/2014/01/sniffing-and-decoding-n...
The TI CC2538 should be safe against attacks in which the flash could be obtained even after a chip erase like in older modules [1].
[1] TI CC2430 Attack http://www.blackhat.com/presentations/bh-usa-09/GOODSPEED/BH...
Seriously, I dislike this trend of making everything a closed and encrypted black box accessible only through official channels (that will disappear in 3 years anyway) for reasons mostly related to money-making and not really security. I think this is will, if continued, slow down the rate of technological progress and development of new ideas.
To quote pg,
"It is by poking about inside current technology that hackers get ideas for the next generation. No thanks, intellectual homeowners may say, we don't need any outside help. But they're wrong. The next generation of computer technology has often—perhaps more often than not—been developed by outsiders."
But then security is important (which is true for almost all wireless stuff), things are quite different. It's pretty hard to build embedded devices which provide basic means of security without having a poor user experience.
So you'll slow down reversing, and probably deter most hobbyists -- but not anyone with anything tangible to gain from breaking your system. Personally I think "obviously insecure" is better than "might be somewhat safe".
Enough of us have more fun reversing or breaking crypto applications :)
CRASH AND BURN